PT-2018-10108 · Cksource+1 · Ckeditor+1

CVE-2018-10795

·

Publicado

2018-05-07

·

Atualizado

2024-08-05

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Liferay versions 6.2.x and earlier
Description The issue concerns an FCKeditor configuration that may allow an attacker to upload or transfer files of potentially dangerous types. These files can be automatically processed within the product's environment via specific URI paths, such as "browser/liferay/browser.html?Type=" or "html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html". It's noted that the vendor disputes this issue, citing that file upload is an expected feature subject to Role Based Access Control checks, which restrict uploads to authenticated users with proper permissions.
Recommendations For Liferay versions 6.2.x and earlier, consider restricting access to the FCKeditor file upload feature to minimize the risk of exploitation, ensuring that only authenticated users with proper permissions can upload files. Additionally, review and enforce Role Based Access Control checks to prevent unauthorized file uploads.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10795

Produtos afetados

Ckeditor
Liferay